aicoolies logo
FuzzyAI logo
FuzzyAI logo

FuzzyAI

CyberArk's open-source LLM fuzzing framework for AI security testing

open sourceupdated Aug 16, 2026

FuzzyAI is CyberArk's Apache-2.0 framework for fuzzing LLM APIs to identify jailbreaks and related security vulnerabilities. Current README examples cover Ollama/local models, OpenAI, Anthropic, custom REST endpoints, and attacks such as ManyShot, Taxonomy, and ArtPrompt. Use it as a repeatable security-testing starting point, not a complete AI risk-management system.

Read our FuzzyAI review

A detailed review by the aicoolies team — click to read

FuzzyAI applies fuzz-testing ideas to large language model APIs by running documented attack examples against configured model targets. Developed by CyberArk's security research team, the Apache-2.0 project currently documents jailbreak-oriented fuzzing plus examples for ManyShot, Taxonomy, and ArtPrompt-style attacks across OpenAI, Anthropic, Ollama/local models, and custom REST APIs.

The framework operates against documented provider examples rather than a guaranteed universal model matrix: OpenAI, Anthropic, Ollama/local models, and custom REST API targets are visible in the current README. Teams that need governance-grade evidence should wrap the CLI output with their own severity taxonomy, storage, and remediation workflow. This evidence-based approach helps security teams quantify LLM risk rather than relying on qualitative assessments of model safety.

With 1.4K+ GitHub stars and CyberArk stewardship, FuzzyAI fills a useful gap for teams that want a repeatable starting point for LLM security testing without building every fuzzing prompt from scratch. The repository was active in the source check, but the latest push observed in this pass was 2026-02-06, so production users should review current issue activity and code paths before standardizing on it.

Pricing

Free and open-source under Apache-2.0

Platforms

Python, any OS, tests any LLM via API

Categories

Tags

Use Cases

Related Tools

computed discovery: shared active categories · kept separate from editor-verified Alternatives

ToolHive mascot logo

ToolHive

Run and govern MCP servers across desktop, CLI and Kubernetes

Open-source MCP runtime and governance platform that runs servers in isolated containers, curates registries, enforces access policies, and operates gateways across desktop, CLI, and Kubernetes.

Open Source
Anamorpher parent Trail of Bits mark

Anamorpher

Craft image-scaling prompt-injection payloads to red-team multimodal AI systems

Open-source red-team toolkit from Trail of Bits that generates image-scaling attack payloads — images that look benign at full resolution but reveal a hidden prompt injection after a multimodal system downsamples them.

freeOpen Source
cai

CAI (Cybersecurity AI)

AI agent framework for offensive security and penetration testing

Alias Robotics' agent framework for building AI-driven offensive-security workflows — reconnaissance, exploitation, privilege escalation, and lateral movement — with multi-agent handoffs and human-in-the-loop control. Source-available, but the core is licensed for non-commercial research use only.

freemiumTelemetry
MEDUSA logo

MEDUSA

AI-first security scanner for LLM, agent, MCP, and RAG codebases

MEDUSA is an AGPL-3.0 AI-first security scanner from Pantheon Security that checks AI and machine-learning applications, LLM agents, MCP workflows, RAG pipelines, repository-poisoning risks, secrets, and agent-specific compromise patterns.

Open Source
iFixAi logo

iFixAi

Open-source diagnostic for AI operational misalignment

iFixAi is an Apache-2.0 diagnostic tool for scoring AI agents and models against operational-misalignment risks such as hallucination, manipulation, sabotage, sandbagging, and oversight evasion.

Open Source
Inspect AI parent UK AISI mark

Inspect AI

UK AI Security Institute framework for LLM safety evaluations

Inspect AI is an MIT-licensed framework from the UK AI Security Institute for running large language model evaluations, including tool use, multi-turn dialogue, model-graded scoring, and reusable evaluation tasks.

Open Source

Used in Stacks

FAQ

What is FuzzyAI?

FuzzyAI is CyberArk's Apache-2.0 framework for fuzzing LLM APIs to identify jailbreaks and related security vulnerabilities. Current README examples cover Ollama/local models, OpenAI, Anthropic, custom REST endpoints, and attacks such as ManyShot, Taxonomy, and ArtPrompt. Use it as a repeatable security-testing starting point, not a complete AI risk-management system.

Is FuzzyAI free?

Yes — FuzzyAI is open source and free to use. Free and open-source under Apache-2.0

Is FuzzyAI open source?

Yes — FuzzyAI is open source.

What are the best FuzzyAI alternatives?

The top editor-verified FuzzyAI alternatives are Prompt Security, Snyk.

How does FuzzyAI score in our review?

Our hands-on review scores FuzzyAI 82/100 overall, based on speed, privacy, and developer-experience testing.